Bug #76671 [Opn->Nab]: bypass strpos verification

From: Date: Fri, 27 Jul 2018 02:00:48 +0000
Subject: Bug #76671 [Opn->Nab]: bypass strpos verification
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-216484@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=76671&edit=1 ID: 76671 Updated by: rasmus@php.net Reported by: guilhermeassmannn at gmail dot com Summary: bypass strpos verification -Status: Open +Status: Not a bug Type: Bug Package: Strings related Operating System: MacOS High Sierra & Ubuntu 16.04 PHP Version: Irrelevant Block user comment: N Private report: N New Comment: strpos() is a low-level string manipulation function. If the string you are parsing has a higher-level meaning, you need to handle that yourself before calling strpos(). That might mean calling urldecode() if you know the string is an encoded url. Previous Comments: ------------------------------------------------------------------------ [2018-07-27 01:33:40] guilhermeassmannn at gmail dot com Description: ------------ The bug is more related to when we send a string with encode to the strpos(), when we sent a string with double encode we were able to bypass the verification, using %2570hp if the case is like strpos($string, "php"). Test script: --------------- $x = $_GET['x']; //?x=file:///var/www/html/readme.%2570hp $pos = strpos($x,"php"); if($pos){ exit("denied"); } $ch = curl_init(); curl_setopt($ch,CURLOPT_URL,"$x"); curl_setopt($ch,CURLOPT_RETURNTRANSFER,true); $result = curl_exec($ch); echo $result; Expected result: ---------------- denied Actual result: -------------- <?php //readme ?> ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=76671&edit=1

« previous php.bugs (#216484) next »